Privacy Policy

Thank you for visiting our website and your interest in our company and services.

For Palácio Tangará as the Data Controller, protecting your Data is a priority. We respect your privacy and ensure the safeguarding of your personal data under data protection laws (particularly LGPD) and regulations issued by the National Data Protection Authority.

In the interest of transparency, Palácio Tangará has established this Privacy Policy with the following objectives:

•    To explain why Palácio Tangará processes your Personal Data;
•    To describe what types of Personal Data related to you Palácio Tangará may collect and how they are retained;
•    To inform you of the rights you have regarding your data and how to exercise them.

This Privacy Policy excludes websites and online services with their own privacy policies and does not incorporate this document by reference or in any other manner.

This Privacy Policy also does not apply to the processing of Personal Data by Oetker Collection and its Affiliates, which have their Privacy Policies available on their websites.


Different privacy policies may also apply to other parts of our online presence, such as pages dedicated to online recruitment.

Our privacy practices may be restricted in certain countries where we operate, reflecting local practices and legal requirements. We will inform you specifically if this is the case.

Palácio Tangará reserves the right to modify this Privacy Policy at any time, noting that any modification will take immediate effect.

Accordingly, we invite everyone to regularly review our Privacy Policy, available on all pages of our website, to stay informed of the most recent applicable online version. For changes we consider most significant, a notification will be posted on the website. We also encourage you to check the date indicated in this Privacy Policy to ensure it reflects the most recent update.

This Privacy Policy is originally written in English and may be translated into other languages. In case of any inconsistencies, the English version shall prevail.

definitions

1. Definitions

For informational purposes:

•    Personal Data refers to any information related to an identifiable natural person (Data Subject) or any individual who can be identified, directly or indirectly, by reference to an identification number or to one or more specific elements (surname, first name, address, email, telephone number, credit card number, location data, electronic identifiers, etc.).

•    LGPD: Brazilian General Data Protection Law – Federal Law No. 13,709/2018.

•    Sensitive Personal Data includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership. It also encompasses genetic data, biometric data for the unique identification of a natural person, and data concerning health, sexual life, or sexual orientation.

•    Processing of Personal Data means any operation performed with Personal Data (collection, storage, transmission, deletion, etc.), whether printed or electronic.

•    Controller is the individual or entity that determines the purposes of each processing activity and the means to achieve these purposes.

•    Processor is an individual or legal entity, public or private, that processes personal data on behalf of the Controller.

•    Oetker Collection refers to Oetker Hotel Management Company GmbH (OHMC), a hotel management company headquartered at Schillerstraße 4/6, 76530 Baden-Baden, Germany.

•    Affiliate refers to companies affiliated with OHMC GmbH through shared management or ownership.

•    Owner means any other companies managed under the Oetker Collection’s hotel activities on behalf of third-party owners.

•    National Data Protection Authority (ANPD) is the body responsible for regulating and overseeing compliance with the LGPD.

•    Data Protection Officer (DPO) is the person responsible for receiving inquiries about how Palácio Tangará processes your Personal Data and your requests to exercise your rights. This individual also serves as a communication channel between Palácio Tangará, you, and the ANPD.

collect-your-data

2. Why Palácio Tangará Needs to Collect Your Data

The data Palácio Tangará collects is necessary to fulfill the following purposes:

•    Reservation Management (room);

•    Stay and Activity Management and other Services, such as the SOU program, social or corporate events, lost and found, valet parking;

•    Payment Management for reserved products, activities, and other Services;

•    Customer Account Management to create and use an account, update personal data, view or modify stay information, or book additional Services;

•    Customer Requests Management (before or during the stay);

•    Management and Effective Delivery of reserved and/or potential stays and services;

•    Commercial Prospecting related to services similar to those previously provided to the client; sending requests, promotional, and informational messages via mail or telephone; sending requests, promotional, and informational messages via email, SMS/MMS;

•    Organization of Competitions and Other Promotional Operations (social media);

•    Satisfaction Surveys following stays;

•    Video Surveillance Management (CCTV);

•    Management of Accesses for Vendors and Service Providers to Palácio Tangará premises;

•    Establishment, Exercise, or Defense of Legal Claims against the organization;

•    Accounting Management (customer records);

•    Requests to Exercise Data Subject Rights under applicable Personal Data Protection legislation;

•    Facilitating Medical Assistance in Emergencies;

In general, Palácio Tangará does not process any of your data for purposes incompatible with those for which they were collected, except with your prior consent.

what-data-palacio-tangara-collects

3. What Data Palácio Tangará Collects?


Palácio Tangará collects various types of Personal Data about you:

personal-data-you-provide-directly

3.1 Personal Data You Provide Directly:

Identity Information: Last name, first names, full address, phone number (landline or mobile), email address, date of birth, job title/position, company affiliation, ID or passport number, client number, credit card number, number of children, children’s dates of birth, and children’s first names.

Payment Information: Postal statement or bank identification, transaction number, check number, credit card number, brand and issuing bank, third-party financing.

Commercial Relationship Data: Customer number, reservation number, document requests, reserved and purchased products and services, quantity, amount, frequency, delivery address, purchase history, origin of sale (seller, representative) or order, customer correspondence, and post-sales service.

Communication Details and Related Metadata: Exchanged correspondence, date and time of messages, feedback, etc.

Newsletter Subscription Information: Job title/position, last name, first name, email address, country of residence, date of birth.

Other Data: Additional types of information that you voluntarily provide to us.

Providing your Personal Data is voluntary. However, certain information is mandatory and essential for Palácio Tangará to process your request, as indicated in our forms. Without this information, Palácio Tangará cannot process your request.

personal-data-provided-to-us

3.2 Personal Data Provided to Us:

From Oetker Collection: We may receive Personal Data collected by Oetker Collection for commercial prospecting and site management, including your Identity and Personal Data related to newsletter subscriptions.

From Affiliates: Personal Data you provide for reservations, including your Identity, Commercial Relationship Data, and Payment Data, may be shared and received jointly with Affiliates you previously visited to meet your requests and reservation preferences.

From Other Owners: Oetker Collection manages hotels and other properties on behalf of third-party Owners. If you reserve a stay in a property managed by an Owner, we will share and receive Personal Data jointly with that Owner, such as your identity, commercial relationship data, payment information, and any service preferences. The use of your Personal Data by the Owners will follow their own privacy practices.

From Social Media: Information from social media accounts, profile photos, or posts.

From Other Sources: We may receive your Personal Data from other sources, such as public databases, marketing partners associated with your service settings, and other third parties, including online booking services, travel agencies, airlines, credit card partners, and others offering branded products and services. These usually include your identity, social media details, feedback, and other data you voluntarily provide to us.

personal-data-we-collect-automatically

3.3 Personal Data We Collect Automatically:

Technical Data Required for Site Use: We automatically collect certain information about you when you access Palácio Tangará’s website, specifically, details about your device, browsing (browser type and version, operating system, Internet provider, device IP address, date and time of access, the website from which users access this site, and pages visited). Palácio Tangará uses Cookies and other tracking technologies to gather information when you use its website. For more information on Cookies and how to manage them, see our Cookie Policy.

Location-based and Wi-Fi Services: To provide Wi-Fi services in our hotels and other properties, we may collect device identifiers (like IP address or other unique identifiers). With your consent, we may also gather physical location data from your device using Wi-Fi or other technologies to offer personalized location-based services, such as customized promotions or assistance in finding a nearby hotel.

CCTV/Surveillance: For your safety, visual recordings and images are collected through closed-circuit television (CCTV) during your visit to a Palácio Tangará property, when permitted by applicable law.

sensitive-personal-data

3.4 Sensitive Personal Data

You may provide, or we may collect, what is classified as Sensitive Personal Data. For example, you may share health or dietary information to allow us to accommodate you during your stay and offer services that consider your specific needs.
In such cases, we process Sensitive Personal Data only to the extent possible and as required by applicable law, such as to protect your life in an emergency or with your explicit consent. Unless otherwise required by law, you are not obligated to provide any Sensitive Personal Data. If you choose not to, this decision will not prevent you from using our Services.

In this case, we only process Sensitive Personal Data if and to the extent permitted and required by applicable law, such as to protect your life in case of emergencies, or with your express consent. Unless otherwise required by applicable law, you are not required to provide us with any of your Sensitive Personal Data. Should you choose not to, your decision would not prevent you from using our Services.

4. Legal Basis for Processing Your Data

Palácio Tangará collects your Personal Data for the purposes described in Section 2 of this Policy. Palácio Tangará only collects and processes your data when it has a legal basis to do so.

contractual-relationships

4.1 Contractual Relationships with Palácio Tangará:

Your data is necessary to execute the contract you signed or intend to sign, including making/completing your reservation, managing your stay, and providing goods and services you requested. Under this contractual legal basis, any refusal to provide your Personal Data will prevent the contract’s formation and execution.

4.2 Legal Obligations Binding on Palácio Tangará:

Some of your Data is processed by Palácio Tangará to comply with legal obligations, such as responding to legal proceedings, fulfilling requests from public authorities worldwide, or from public-sector agencies performing public service duties, in line with applicable laws, and seeking available solutions or limiting harm to ourselves or others.

Additionally, your data is processed to manage requests to exercise rights granted to Data Subjects under applicable Personal Data Protection legislation.

4.3 Your Consent:

Palácio Tangará will obtain your consent to process Sensitive Personal Data you may have provided related to your stay (e.g., dietary restrictions or special accommodations for physical or medical conditions). Your consent may also be required when we use cookies and other tracking technologies as outlined in our Cookie Policy. We will also request your consent for participation in contests and other promotional activities we organize on social media, according to applicable legal requirements.

You may change your preferences and withdraw your consent at any time, as described in Section 6.2 of this Policy, without affecting the lawfulness of processing based on consent carried out prior to withdrawal.

protecting-the-life

4.4 Protecting the Life or Physical Integrity of Data Subjects or Third Parties:

In certain circumstances, it may be necessary to process your Personal Data, including Sensitive Personal Data you provided through our Services, when it is in your vital interest or that of third parties, for example, in a medical emergency.

legitimate-interests

4.5 Legitimate Interests of Palácio Tangará:

Palácio Tangará may process your Personal Data based on legitimate interests to communicate with you (email/SMS) during your stay, send promotional offers, newsletters, business information, and other marketing communications. You may object to these communications at any time, as outlined in Section 6.2 of this Policy.

We also process your Personal Data to meet our legitimate business interests, such as providing superior customer service, personalizing your stay experience, maintaining our Services' security, and protecting our operations or those of our affiliates or third parties. Furthermore, we process your data to distribute and respond to surveys about your experience, provide information upon your request, answer your questions, and ensure the security of our Services.

4.6 Exercising Palácio Tangará’s Rights in Legal and Administrative Actions or Arbitration:

Even after your relationship with us ends, we may process some of your Personal Data to exercise our legally guaranteed rights, including as evidence in judicial, administrative, or arbitration proceedings.

recruitment

4.7 Recruitment :

We post job openings on specialized sites, receive applications and resumes on our website, employee referrals, and resumes left at the hotel. In these situations, we process your Personal Data to review your resume, verify qualifications, and determine whether you meet the specific requirements of the role, as well as to support the recruitment process (e.g., through phone or email contact and scheduling interviews).

fraud-prevention

4.8 Fraud Prevention and Ensuring Your Security:

We may process your Personal Data to ensure your safety (and that of third parties) and prevent identification fraud during access to our website and internal systems. We have measures to detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activities, correct errors, and verify customer information.

retention-period-of-your-personal-data

5. Retention Period of Your Personal Data

Your Data is retained by Palácio Tangará for as long as necessary to fulfill the purposes outlined in Section 2 of this document, in addition to statutory prescription periods.

Examples (these durations may vary according to national laws and regulations):

Commercial Relationship Management

Personal Data related to customers is retained only for the period strictly necessary to manage the business relationship. However, data that can serve as evidence of a right or a contract, or data kept to fulfill a legal obligation, will be retained for no longer than necessary for these purposes, according to applicable provisions (in particular, but not limited to, the provisions in the LGPD, Civil Code, and Consumer Code).

Credit Card Data

These details will be deleted once the transaction has been completed (upon payment), which may be deferred until receipt of the goods, plus, if applicable, the resolution period for distance and off-premises contracts. In the case of payment by credit card, the card number and expiration date may be retained as proof in case of any transaction dispute for the legally specified period. These details will only be used if there is a dispute regarding the transaction.

This credit card data may be retained for a longer period if you give your express consent to facilitate payment for your future orders.

The visual cryptogram data will not be retained beyond the time needed to complete each transaction, even in cases of successive payments or card retention for future purchases.

When the credit card’s expiration date is reached, the related data will be deleted.

Commercial Prospecting Management

Customer data used for commercial prospecting is retained for three (3) years from the end of the business relationship (e.g., a purchase or the last customer contact).

Personal Data related to non-customer prospecting will be retained for three years from the date of collection or the last contact with the potential customer (e.g., a request for documentation or a click on a hyperlink in an email).

For more details on your data retention periods, please contact Palácio Tangará (see Section 6.2 of this Policy).

your-rights-and-how-to-exercise-them

6. Your Rights and How to Exercise Them

your-rights

6.1 Your Rights

Right of Access: You may obtain confirmation from Palácio Tangará on whether your Personal Data is being processed and, if so, access all Personal Data and information retained by Palácio Tangará.

Right to Rectification: You may request from Palácio Tangará, as promptly as possible, the rectification of any inaccurate or incorrect data about you. You may also request that your data be completed, if necessary.

Right to Erasure or Objection: Subject to legal exceptions, you may request Palácio Tangará to anonymize, block, or delete your Personal Data as quickly as possible if, in particular, you believe that the processing carried out by Palácio Tangará is excessive, incompatible with applicable law, or no longer necessary for the purposes for which it was collected.

Right to Data Portability: Subject to practical limitations, you may request Palácio Tangará to transmit your Personal Data to another provider or service provider according to specific ANPD regulations on this matter.

Right to Review Decisions Based Solely on Automated Processing: You may request Palácio Tangará to review any decision made solely on automated processing related to your personal, professional, consumer, credit profile, or aspects of your personality.

Right to Withdraw Consent for Data Processing: You may request Palácio Tangará to delete your Personal Data when the processing is based on your consent (see Section 6.2 of this Policy).

Right to Deny or Withdraw Consent for Data Processing: When processing your Personal Data is based on your consent, you may deny or withdraw it at any time (see Section 6.2 of this Policy). In this case, Palácio Tangará will inform you of the consequences of not proceeding with the processing.

Right to Know Who Shares Your Data: You may request Palácio Tangará to inform you about who your data has been shared with.

Right to Lodge a Complaint with the Competent Supervisory Authority: If you believe your rights are not being respected or that your data protection is not assured under the applicable Personal Data Protection legislation, you may file a complaint with the competent supervisory authority at any time (in Brazil: directly on the ANPD website or by mail to: Rua Deputado Laércio Corte, 1.501 - Panamby - 05706-290 - São Paulo, SP - Brazil).

Right to Request Clauses Used for International Data Transfers: You may request from Palácio Tangará the clauses that form the basis for international data transfer operations, respecting commercial and industrial secrets contained within this material.

exercise-your-rights

6.2 Exercising Your Rights

To exercise any of your rights, submit your request:
By Email: privacy.tangara@oetkercollection.com

By Mail: DPO - Palácio Tangará, Rua Deputado Laércio Corte, 1501 – Panamby - São Paulo - SP, 05706-290 - Brazil

DPO: Vainzof Lima e Karassawa Sociedade de Advogados

The request should specify in the subject line the reason for the request (right of access, right to erasure, etc.), the address for sending the response, and the entity to which the request applies (Palácio Tangará).

To exercise your rights, you must provide proof of your identity. When Palácio Tangará has reasonable doubts about your identity, additional information may be required to confirm it.
Palácio Tangará will respond to your request as quickly as possible, following the LGPD.

If you believe, after contacting Palácio Tangará, that your rights are still not being respected, you may file a complaint with the competent supervisory authority.

Commercial Prospecting and Targeted Advertising:

Please note that we only send commercial prospecting messages when we have your prior express consent, except when we obtained your data during a sale or negotiation for a product or service, and the commercial prospecting is limited to marketing related to those products or services.

After opting to receive offers from Palácio Tangará, you may reconsider and opt out at any time:

Commercial Emails: Use the unsubscribe link at the bottom of the email. Please note that even if you unsubscribe from commercial emails, we may still send you non-commercial (transactional) emails related to your account and transactions through the Services.

In general, for any questions regarding this Privacy Policy or any requests related to Palácio Tangará’s management of your Personal Data, you can submit your request via email or regular mail, as indicated above.

shares-your-data

7. When and With Whom Palácio Tangará Shares Your Data?

Access to your Personal Data is strictly limited to entities and their authorized teams that need to process it as part of their responsibilities.

Palácio Tangará may also transfer your Personal Data to the following entities when necessary to fulfill one of the purposes stated in Section 2 of this document:

Oetker Collection: We may share the Personal Data you provide with the Oetker Collection as part of hotel activities managed on behalf of third-party Owners.

Affiliates: Personal Data you provide in relation to reservations is shared and received jointly with Affiliates you have previously visited to meet your requests and reservation preferences.

Other Owners: Oetker Collection manages hotels and other properties on behalf of third-party Owners (“Owners”). If you make a reservation to stay at a property managed by an Owner, we will share and receive Personal Data jointly with that Owner, such as your identity, commercial relationship data, payment information, and any notes regarding your service preferences.

Operators, including hosting and maintenance providers, payment service providers, fraud prevention and detection providers, logistics suppliers, marketing solutions providers, commercial prospecting and communication management providers, customer service providers, data analysis service providers, etc.

Service Providers at Our Hotels: We may share your Personal Data with providers who offer services such as spa treatments, salons, and restaurants at our hotels or other properties, or event planners and organizers for any event you plan or organize with us.

Internet Service Providers: We may partner with a limited number of providers to offer Internet access to our guests. Your use of Internet services is subject to the terms and privacy policy of the third-party Internet provider, accessible via links on the service login page or the provider’s website.

Transportation Providers: We may share your Personal Data with third parties, such as car rental agencies, to help arrange rental vehicles for you. Additionally, we work with third parties, including travel agencies and airlines. This Privacy Policy does not apply to information you provide directly to these third parties.

Anonymized Data Sharing: We may share data anonymously with third-party providers, which does not reveal Personal Data.

Social Media: If you connect to one of our social media pages, we may share some of your Personal Data with your friends associated with your social media account, other users of the site, and your social media account provider, in connection with your social sharing activities. We may make reviews, message boards, blogs, and other user-generated content available to users through our Services. Any information disclosed in these areas is public, so you should exercise caution when disclosing your Personal Data in this context. We are not responsible for the privacy practices of other users, including operators of the web networks to which you provide information.

Other Partners, Consultants, and Advisors: We may share your Personal Data with other partners, consultants, and advisors who provide us with services, including financial institutions, external auditors, attorneys, and credit card issuers.

Business Transfers: In the event we sell our business, hotels, or other assets, or cease managing a hotel or property, we may include Personal Data collected about you or control over this Personal Data as a business asset in any transfer. We may also disclose your Personal Data to a buyer or other successor in the event of a merger, sale, or other transfer, where Personal Data we hold about our users is among the assets transferred.

In compliance with legal obligations, your Personal Data may be disclosed to authorized third parties, such as organizations, judicial officers, and public officials, for debt collection.

Palácio Tangará does not sell, rent, or share your Personal Data without your consent, except as provided in this Privacy Policy or for purposes disclosed in any online form or at the Services unit where you provide Personal Data. Palácio Tangará also does not engage in selling your Personal Data.

are-your-data-transferred-outside-brazil

8. Are Your Data Transferred Outside Brazil?

Your Personal Data is hosted on secure servers located within the European Union and the European Economic Area.

Additionally, your Data may be transferred outside Brazil, particularly when processed by employees operating outside the country who work for us, for the Oetker Collection, Affiliates, other Owners, or data processors acting on our behalf.

Your Personal Data will be transferred through secure connections, such as encryption and access control. The transfer duration is limited to the period necessary to fulfill the purposes established in this policy.

The agents who process your Personal Data are responsible for ensuring compliance with applicable legislation. We implement stringent technical and organizational security measures to protect your Data during international transfers and to ensure that only authorized individuals have access.

We give special attention to the processing of Personal Data to ensure your information is handled in accordance with current Personal Data Protection laws. If data is transferred to a country not subject to an adequacy decision by the National Data Protection Authority (ANPD), a standard contract or Binding Corporate Rules will be prepared, as required by applicable legislation.

The table on this link summarizes the international data transfer operations carried out by Palácio Tangará.

protects-your-data-processing

9. How Palácio Tangará Protects Your Data Processing?

Palácio Tangará implements technical, physical, and organizational measures to ensure the security and confidentiality of your Personal Data during collection, processing, and transfer.

Palácio Tangará’s infrastructures are protected against malicious software (viruses, spyware, etc.). Physical and remote access to servers hosting the Data is controlled. Regular penetration testing is conducted, along with regular backups and restoration testing. The security of the device you use to connect to our website is your responsibility.

If Palácio Tangará engages service providers to process part of your Personal Data, we are committed to verifying that they offer sufficient guarantees to protect the Personal Data entrusted to them and to having them sign confidentiality clauses, as required by applicable Personal Data Protection legislation.

In the event of a Personal Data Breach—an incident that compromises the integrity, confidentiality, or availability of your Personal Data, whether intentional or not—Palácio Tangará is committed to fulfilling the obligations required by the applicable Personal Data Protection legislation.

10. Cookie Policy

To learn more about Cookies and how to manage them, please refer to our Cookie Policy.

social-media

11. Social Media

Palácio Tangará is active on Social Media platforms, specifically Instagram, Facebook, YouTube, WeChat, SINA Weibo, etc.

Accessing these Social Media platforms implies prior acceptance of their terms, including commitments under applicable Personal Data Protection laws for data processing conducted by these platforms, independently of Palácio Tangará’s pages on these platforms.

To learn more about how your Personal Data is protected when browsing these Social Media platforms, Palácio Tangará invites you to consult the respective Privacy Policies:

Palácio Tangará may collect some of your personal data when you navigate our Social Media pages, "like" our pages, share content, or follow us on Social Media.

Additionally, if you choose to log in, connect, or link to the Services using your Social Media account, some of your personal data will be shared with us according to your settings on that Social Media service, such as location, check-ins, activities, interests, photos, status updates, as well as personal data that may be part of your profile or a friend's profile.

Palácio Tangará may, in the context of organizing contests, collect your last name, first name, date of birth, profile photo when necessary, gender, networks, Social Media user ID, and any public information. In general, Palácio Tangará may collect your Personal Data in the context of Social Media usage.

privacy-by-design

12. Privacy By Design/by Default

Palácio Tangará is committed to integrating the protection of Personal Data by Design and by Default into any project, service or any other tool related to the processing of Personal Data, specifically the reduction of Personal Data, limitation of the purposes of data collection, respect for the integrity and confidentiality of data, limitation of retention periods.

accountability

13. Accountability

Respecting the principle of Accountability, Palácio Tangará:

adopts internal procedures to ensure compliance with the legislation applicable to the protection of Personal Data (IT charter, personal data protection charter, etc.);

maintains a documentary record of any processing carried out under its responsibility or that of the contracted party for processing (maintenance of the processing record, confidentiality agreements for employees and service providers, company security policy, procedures for managing access requests, rectification, opposition...);

conducts Privacy Impact Assessments for processing operations that present specific risks in relation to rights and freedoms.

The objective is to provide abundant documentation demonstrating compliance with data protection rules at all times.

Last updated: October 31, 2024.

personal data